Is there any meaningful security benefit to one time codes being more than 4-6 digits?
(For any of TOTP, email, or sms delivery.)
Is there any meaningful security benefit to one time codes being more than 4-6 digits?
(For any of TOTP, email, or sms delivery.)
@adamshostack they make people feel more secure
@ryanc I don't mean to be snarky, but, really? Is this a studied thing?
@adamshostack I'm not aware of any such study. I was being a bit flippant, honestly it's probably more about how the people making decisions about implementing them feel.
Longer ones make issues related to rate limits and race conditions less relevant.
My bank uses eight alphanumeric characters for logging into online banking and making transfers, but six digits for online debit card transactions.
This doesn't seem coherent to me, but I really don't want to think too much about their backend.
You might look for papers which cite this: https://dl.acm.org/doi/abs/10.1145/3473040
@ryanc Well that’ll teach me to take you seriously! 😂
@adamshostack I make a point of deadpan delivery of unserious content in order to establish a pattern that provides plausible deniability.
@ryanc Surely…
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.